Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Incorrect, DKIM also signs the body of the message.


You're right and I was wrong.

The DKIM signer selects a list of headers (h=) to be signed, but the body is always implicitly included (and thus not listed). I was confused because I thought there needed to be a flag to include it, and had never seen such from Gmail or others.

For anyone else that's curious: https://rfc-editor.org/rfc/rfc6376#section-3.7


Only from the mail server to the receiving mail server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: